QuestionQ8

Threat Hunting Techniques

Refer to the exhibit.

Question Image

A company's cybersecurity team detects an active attack against the web server hosting the company website. After analyzing web application firewall logs, the team finds several Base64-encoded HTTP requests. The team decodes the payloads and obtains the HTTP requests.

What did the attackers use to exploit the server?

Explanation

The payload appends SQL statements to a request parameter and uses database functions such as SELECT, substring, ascii, CASE, and conditional SLEEP delays to infer password data. This is a time-based blind SQL injection attack.

Community Discussion

No comments yet. Be the first to start the discussion!